There are 14 NERC CIP standards, and penalties for missing them can run $1.4M a day. MERIDIAN checks every SCADA command, every access event, and every grid operation in real time. So when auditors show up, you don't scramble to prepare. You just show them the dashboard.
NERC enforcement is active and it's picking up speed. These penalties are real, they're documented, and they're growing.
FERC's penalty guidelines allow up to $1.4M per day per violation for CIP non-compliance. Enforcement actions have already cost some utilities tens of millions of dollars in a single settlement.
Duke Energy: $2.7M · PG&E: $10M settlement · Average enforcement up 340% since 2019Physical attacks on grid infrastructure have surged since 2022. CIP-006 and CIP-014 require you to log and prove every physical access event. Manual logs don't hold up once enforcement starts digging.
NERC GridEx data · DHS CISA advisory AA22-265A · 2023 substation incidentsNERC CIP-015 makes internal network security monitoring mandatory for high- and medium-impact BES Cyber Systems. Right now, most utilities don't have tools that meet the standard. The deadline is October 2028.
NERC CIP-015-1 · FERC Order 887 · Effective enforcement Q4 2028Six areas of coverage that together answer every NERC CIP evidence request an auditor can make.
Every grid operation, whether it's a breaker operation, a setpoint change, or a load shedding command, generates an ML-DSA-65 signed receipt in real time. Nothing happens without a record.
ML-DSA-65 · FIPS 204 · per-commandEvery badge swipe, electronic login, and physical access event gets logged with identity, timestamp, and authorization context, all signed. That covers CIP-004 and CIP-006.
CIP-004 · CIP-006 · identity-boundYou get real-time alerts with an evidence chain nobody can change. Every anomaly, whether it's an unauthorized access attempt, a configuration change, or a network intrusion, gets logged, signed, and time-stamped before you're even alerted.
CIP-007 · CIP-008 · CIP-015One screen shows your compliance status across all 14 CIP standards. Export an auditor-ready report in one click. Gap analysis updates itself as your environment changes.
14 CIP standards · real-time · exportableEvery signature uses ML-DSA-65, also called CRYSTALS-Dilithium, the standard NIST picked as FIPS 204. It's CNSA 2.0 ready and built for the NSA's 2030 post-quantum mandate. Records signed today can still be checked in 2040.
CNSA 2.0 · FIPS 204 · 2030 mandate readyAuditors can check any evidence package in 8.6ms without needing network access. Each signed receipt is self-contained, so there's no Hive infrastructure to reach, no API call, no internet connection needed. It works in air-gapped environments too.
8.6ms · offline · air-gap readyMERIDIAN generates evidence for every NERC CIP standard in scope. No gaps, no manual log exports, and no scrambling before an audit.
MERIDIAN's compliance dashboard shows your real-time standing across all 14 CIP standards. Every number is backed by a signed chain of evidence.
MERIDIAN works with the OT security stack you already have. Your SCADA systems stay untouched. Your auditors see results in 30 days.
MERIDIAN adds a layer of signed proof. It doesn't replace anything. It plugs into the OT security infrastructure you already run.
Here's why the usual approaches leave utilities exposed, and what MERIDIAN does differently.
| Capability | Manual Logs + Spreadsheets | Existing NERC Tools | MERIDIAN |
|---|---|---|---|
| Real-time attestation | Manual, delayed | Batch, next-day | Sub-second, every event |
| Post-quantum signatures | None | None | ML-DSA-65 / FIPS 204 |
| Court-admissible evidence | Disputed in enforcement | Partial | Cryptographic, tamper-evident |
| CIP-015 ready | Not addressed | Partial roadmap | Fully covered |
| Offline verification | N/A | Requires connectivity | 8.6ms, air-gap ready |
| Cost per signed event | Immeasurable liability | $0.08 to $0.40 | Fixed annual, $150K/yr |
| Audit package generation | Weeks of manual work | Days, manual export | One-click, instant |
| SCADA command logging | Incomplete, mutable | Vendor-dependent | 100%, cryptographically signed |
NERC enforcement affects every regulated utility. These are the organizations that move first.
You've received a Notice of Penalty or a compliance violation finding. Your legal team is managing the settlement. You need evidence you can defend going forward, and you need it fast.
You coordinate reliability across dozens of member utilities. Each one has its own NERC CIP status and its own audit cycle. Pulling evidence together from all of them by hand is a nightmare every quarter.
CIP-015's internal network security monitoring rules are final. The compliance date is October 2028. Most utilities don't have tools that generate the evidence it requires. The window to build it is closing.
$150,000/year. $1.4M/day is the alternative.
Pilot deployment takes four weeks and covers all the CIP standards, for a fixed annual cost. No per-event billing, and no infrastructure for you to run.
Patent Pending · CNSA 2.0 · FIPS 204 · CIP-015 Ready · ML-DSA-65